Hi niketnilay, Thanks for stepping in, appreciate the prompt response. I might have phrased my question not so clear, what I’m trying to do is Ivactually need to know which of the indexes has the 'true' value in this. The best solution for me will be some kind of way to iterate this structure like in programming- message.anomaly.features.anomaly{}[0],message.anomaly.features.anomaly{}[1] and so on.. Is this something that is possible to accomplish using splunk? Thanks again,
... View more